Aterm HC100RC Ver1.0.1 and previous versions allows attacker with administrator rights to execute arbitrary OS commands via import.cgi encKey parameter.
nec aterm_hc100rc_firmware